Live data from Hacker News

Public secrets exposure leads to supply chain attack on GitHub CodeQL

praetorian.com

1–10 of 66 posts

Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL

#4
post #3
post #2

They weren’t kidding on the response time. Very impressive from GitHub.

Not very impressive to have an exposed public token with full write credentials...

Trying my best not to break the no snark rule [1], but I'm sure your code is 100% bullet proof against all current and future-yet-invented-attacks.

[1] _and failing_.

Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL

#6
No mention why this temp token had rights to do things like create a new deployments and generate artifact attestations?

For their fix, they disabled debug logs...but didn't answer if they changed the temp tokens permissions to something more appropriate for a code analysis engine.

Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL

#7
post #3
post #2

They weren’t kidding on the response time. Very impressive from GitHub.

Not very impressive to have an exposed public token with full write credentials...

Perfect security does not exist. Their security system (people, tech) operated as expected with an impressive response time. Room for improvement, certainly, but there always is.

Edit: Success is not the absence of vulnerability, but introduction, detection, and response trends.

(Github enterprise comes out of my budget and I am responsible for appsec training and code IR, thoughts and opinions always my own)

Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL

#9
post #4
post #3

Earlier quoted context omitted.

Not very impressive to have an exposed public token with full write credentials...

Trying my best not to break the no snark rule [1], but I'm sure your code is 100% bullet proof against all current and future-yet-invented-attacks. [1] _and failing_.

[flagged]
Post reply on HN